ALT-PU-2022-3741-1
Package epiphany updated to version 41.3-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2022-05569
Уязвимость реализации сценария ephy-about:overview веб-браузера Epiphany, позволяющая нарушителю проводить межсайтовые сценарные атаки
Modified: 2024-11-21
CVE-2021-45085
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.
- https://gitlab.gnome.org/GNOME/epiphany/-/issues/1612
- https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1045
- https://lists.debian.org/debian-lts-announce/2022/08/msg00006.html
- https://www.debian.org/security/2022/dsa-5042
- https://gitlab.gnome.org/GNOME/epiphany/-/issues/1612
- https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1045
- https://lists.debian.org/debian-lts-announce/2022/08/msg00006.html
- https://www.debian.org/security/2022/dsa-5042
Modified: 2024-11-21
CVE-2021-45086
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.
- https://gitlab.gnome.org/GNOME/epiphany/-/issues/1612
- https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1045
- https://www.debian.org/security/2022/dsa-5042
- https://gitlab.gnome.org/GNOME/epiphany/-/issues/1612
- https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1045
- https://www.debian.org/security/2022/dsa-5042
Modified: 2024-11-21
CVE-2021-45087
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.
- https://gitlab.gnome.org/GNOME/epiphany/-/issues/1612
- https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1045
- https://lists.debian.org/debian-lts-announce/2022/08/msg00006.html
- https://www.debian.org/security/2022/dsa-5042
- https://gitlab.gnome.org/GNOME/epiphany/-/issues/1612
- https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1045
- https://lists.debian.org/debian-lts-announce/2022/08/msg00006.html
- https://www.debian.org/security/2022/dsa-5042
Modified: 2024-11-21
CVE-2021-45088
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
- https://gitlab.gnome.org/GNOME/epiphany/-/issues/1612
- https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1045
- https://lists.debian.org/debian-lts-announce/2022/08/msg00006.html
- https://www.debian.org/security/2022/dsa-5042
- https://gitlab.gnome.org/GNOME/epiphany/-/issues/1612
- https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/1045
- https://lists.debian.org/debian-lts-announce/2022/08/msg00006.html
- https://www.debian.org/security/2022/dsa-5042